SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Explorer

Which vulnerabilities actually matter?

Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.

CVE Analysis Report · 2026-09-22 edition · PDF

The year’s CVEs, on paper.

Every CVE published this year by month, severity and exploitability, the vendors carrying the volume, how the exploited minority scores on EPSS, and the KEV additions and public exploits to check against your estate. Built from the same data as this page, refreshed daily. Tell us where to send it.

Free · PDF · No newsletter attached

We keep your name and email so we know who asked. UK Cyber Defence Ltd is the controller; see the privacy notice for the rest.

The year’s CVE activity with KEV, EPSS and exploit data as a PDF: heatmaps, a vendor treemap, and the lists worth checking against your estate.

396,388 CVEs1,721 in CISA KEV17,157 with EPSS ≥ 10%25,049 with a public exploitUpdated 22 September 2026

25,049 results · page 144 of 501

CVESummaryPriorityPublished
CVE-2013-1868Multiple buffer overflows in VideoLAN VLC media player 2.0.4 and earlier allow remote attackers to cause a denial of service (crash) and execute arbitrary code via vectors related to the (1) freetype renderer and (2) HTML subtitle parser.EXPLOITHIGH 9.3EPSS 11.0%10 July 2013
CVE-2013-3174DirectShow in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, and Windows Server 2012 allows remote attackers to execute arbitrary code via a crafted GIF file,…EXPLOITHIGH 9.3EPSS 32.0%10 July 2013
CVE-2013-3166Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to inject arbitrary web script or HTML via vectors involving incorrect auto-selection of the Shift JIS encoding, leading to cross-domain…EXPLOITMEDIUM 4.3EPSS 16.3%10 July 2013
CVE-2013-3164Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."EXPLOITHIGH 9.3EPSS 23.6%10 July 2013
CVE-2013-3163Microsoft Internet Explorer Memory Corruption VulnerabilityKEVEXPLOITHIGH 8.8EPSS 70.7%10 July 2013
CVE-2013-3162Microsoft Internet Explorer 7 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than…EXPLOITHIGH 9.3EPSS 25.0%10 July 2013
CVE-2013-3161Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than…EXPLOITHIGH 9.3EPSS 25.0%10 July 2013
CVE-2013-3153Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than…EXPLOITHIGH 9.3EPSS 25.0%10 July 2013
CVE-2013-3152Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than…EXPLOITHIGH 9.3EPSS 23.6%10 July 2013
CVE-2013-3151Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than…EXPLOITHIGH 9.3EPSS 22.8%10 July 2013
CVE-2013-3150Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3145.EXPLOITHIGH 9.3EPSS 25.0%10 July 2013
CVE-2013-3149Microsoft Internet Explorer 7 and 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."EXPLOITHIGH 9.3EPSS 25.0%10 July 2013
CVE-2013-3148Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than…EXPLOITHIGH 9.3EPSS 25.0%10 July 2013
CVE-2013-3147Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."EXPLOITHIGH 9.3EPSS 25.0%10 July 2013
CVE-2013-3146Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than…EXPLOITHIGH 9.3EPSS 23.6%10 July 2013
CVE-2013-3145Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3150.EXPLOITHIGH 9.3EPSS 25.0%10 July 2013
CVE-2013-3144Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than…EXPLOITHIGH 9.3EPSS 22.8%10 July 2013
CVE-2013-3143Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than…EXPLOIT ×2HIGH 9.3EPSS 32.7%10 July 2013
CVE-2013-3115Microsoft Internet Explorer 7 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than…EXPLOITHIGH 9.3EPSS 25.0%10 July 2013
CVE-2013-1300win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in…EXPLOITHIGH 7.2EPSS 12.2%10 July 2013
CVE-2013-4787Android 1.6 Donut through 4.2 Jelly Bean does not properly check cryptographic signatures for applications, which allows attackers to execute arbitrary code via an application package file (APK) that is modified in a way that does not violate the…EXPLOITHIGH 9.3EPSS 58.9%9 July 2013
CVE-2013-2118SPIP 3.0.x before 3.0.9, 2.1.x before 2.1.22, and 2.0.x before 2.0.23 allows remote attackers to gain privileges and "take editorial control" via vectors related to ecrire/inc/filtres.php.EXPLOITHIGH 7.5EPSS 8.98%9 July 2013
CVE-2013-1950The svc_dg_getargs function in libtirpc 0.2.3 and earlier allows remote attackers to cause a denial of service (rpcbind crash) via a Sun RPC request with crafted arguments that trigger a free of an invalid pointer.EXPLOITMEDIUM 4.3EPSS 6.46%9 July 2013
CVE-2013-1362Incomplete blacklist vulnerability in nrpc.c in Nagios Remote Plug-In Executor (NRPE) before 2.14 might allow remote attackers to execute arbitrary shell commands via "$()" shell metacharacters, which are processed by bash.EXPLOITHIGH 7.5EPSS 65.7%9 July 2013
CVE-2013-4786The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote attackers to obtain password hashes and conduct offline password guessing attacks by obtaining the HMAC from a RAKP message 2…EXPLOITHIGH 7.5EPSS 75.0%8 July 2013
CVE-2013-1414Multiple cross-site request forgery (CSRF) vulnerabilities in Fortinet FortiOS on FortiGate firewall devices before 4.3.13 and 5.x before 5.0.2 allow remote attackers to hijack the authentication of administrators for requests that modify (1) settings…EXPLOITMEDIUM 5.1EPSS 2.29%8 July 2013
CVE-2013-3299RealNetworks RealPlayer 16.0.2.32 and earlier allows remote attackers to cause a denial of service (resource consumption or application crash) via an HTML document containing JavaScript code that constructs a long string.EXPLOITMEDIUM 4.3EPSS 2.23%6 July 2013
CVE-2013-3563Stack-based buffer overflow in db_netserver in Lianja SQL Server before 1.0.0RC5.2 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted string to TCP port 8001.EXPLOITHIGH 7.5EPSS 49.5%4 July 2013
CVE-2013-2343Unspecified vulnerability on the HP LeftHand Virtual SAN Appliance hydra with software before 10.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1510.EXPLOITHIGH 10.0EPSS 61.8%2 July 2013
CVE-2013-2171The vm_map_lookup function in sys/vm/vm_map.c in the mmap implementation in the kernel in FreeBSD 9.0 through 9.1-RELEASE-p4 does not properly determine whether a task should have write access to a memory location, which allows local users to bypass…EXPLOIT ×2MEDIUM 6.9EPSS 6.94%2 July 2013
CVE-2013-4098ServerAdmin/ErrorViewer.jsp in DS3 Authentication Server allow remote attackers to inject arbitrary error-page text via the message parameter.EXPLOITMEDIUM 5.0EPSS 4.36%28 June 2013
CVE-2013-4097ServerAdmin/TestDRConnection.jsp in DS3 Authentication Server allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in a -REG-E-OPEN error message.EXPLOITMEDIUM 5.0EPSS 7.30%28 June 2013
CVE-2013-4096ServerAdmin/TestTelnetConnection.jsp in DS3 Authentication Server allows remote authenticated users to execute arbitrary commands via shell metacharacters in the HOST_NAME field.EXPLOITHIGH 9.0EPSS 9.10%28 June 2013
CVE-2013-4095plain/actionsets.html in the SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote authenticated users to execute arbitrary commands via a task with a [command].value field in conjunction with an…EXPLOITMEDIUM 6.5EPSS 5.88%28 June 2013
CVE-2013-4094The Key Management feature in the SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote authenticated users to upload executable files via the (1) private_key or (2) public_key parameter in a…EXPLOITMEDIUM 6.5EPSS 5.63%28 June 2013
CVE-2013-4093The SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote attackers to obtain sensitive information via (1) a direct request to dwr/call/plaincall/AsyncOperationsContainer.getOperationState.dwr, which…EXPLOITMEDIUM 5.0EPSS 6.88%28 June 2013
CVE-2013-4092The SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows context-dependent attackers to obtain sensitive information by leveraging the presence of (1) a session ID in the jsessionid field to secsphLogin.jsp or…EXPLOITMEDIUM 5.0EPSS 4.87%28 June 2013
CVE-2013-4091The SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 does not have an off autocomplete attribute for the password (aka j_password) field on the secsphLogin.jsp login page, which makes it easier for remote attackers…EXPLOITHIGH 7.5EPSS 5.59%28 June 2013
CVE-2013-4660The JS-YAML module before 2.0.5 for Node.js parses input without properly considering the unsafe !!js/function tag, which allows remote attackers to execute arbitrary code via a crafted string that triggers an eval operation.EXPLOITMEDIUM 6.8EPSS 17.3%28 June 2013
CVE-2013-1690Mozilla Firefox and Thunderbird Denial-of-Service VulnerabilityKEVEXPLOITHIGH 8.8EPSS 69.0%26 June 2013
CVE-2013-4631Huawei AR 150, 200, 1200, 2200, and 3200 routers, when SNMPv3 is enabled, allow remote attackers to cause a denial of service (device crash) via malformed SNMPv3 requests that leverage unspecified overflow issues.EXPLOITHIGH 7.8EPSS 3.82%20 June 2013
CVE-2013-4630Stack-based buffer overflow on Huawei AR 150, 200, 1200, 2200, and 3200 routers, when SNMPv3 debugging is enabled, allows remote attackers to execute arbitrary code via malformed SNMPv3 requests.EXPLOITHIGH 7.6EPSS 3.91%20 June 2013
CVE-2012-6568Buffer overflow in the back-end component in Huawei UTPS 1.0 allows local users to gain privileges via a long IDS_PLUGIN_NAME string in a plug-in configuration file.EXPLOITMEDIUM 6.9EPSS 0.61%20 June 2013
CVE-2012-4960The Huawei NE5000E, MA5200G, NE40E, NE80E, ATN, NE40, NE80, NE20E-X6, NE20, ME60, CX600, CX200, CX300, ACU, WLAN AC 6605, S9300, S7700, S2300, S3300, S5300, S3300HI, S5300HI, S5306, S6300, S2700, S3700, S5700, S6700, AR G3, H3C AR(OEM IN), AR 19, AR 29,…EXPLOITMEDIUM 6.5EPSS 3.45%20 June 2013
CVE-2013-1612Buffer overflow in secars.dll in the management console in Symantec Endpoint Protection Manager (SEPM) 12.1.x before 12.1.3, and Symantec Endpoint Protection Center (SPC) Small Business Edition 12.0.x, allows remote attackers to execute arbitrary code…EXPLOITHIGH 7.9EPSS 4.38%20 June 2013
CVE-2013-2472Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and…EXPLOITHIGH 10.0EPSS 23.0%18 June 2013
CVE-2013-2470Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and…EXPLOITHIGH 10.0EPSS 23.0%18 June 2013
CVE-2013-2465Oracle Java SE Unspecified VulnerabilityKEVEXPLOITCRITICAL 9.8EPSS 98.8%18 June 2013
CVE-2013-2460Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to…EXPLOITHIGH 9.3EPSS 70.2%18 June 2013
CVE-2013-3520VMware vCenter Chargeback Manager (aka CBM) before 2.5.1 does not proper handle uploads, which allows remote attackers to execute arbitrary code via unspecified vectors.EXPLOITHIGH 7.5EPSS 55.6%17 June 2013

How to read this

CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.

Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.